Introduction
RFMS has developed a comprehensive approach to meeting many of the needs required by SOX regulations in its RFMS core business system, in the Enhanced Revenue Recognition Method Accounting (ERRM) and it its Enterprise Manager Security System. These RFMS applications support and provide system and security controls over the general ledger, inventory, payroll, accounts payable, banking and sales reporting functions and provide the control reports, audit trails and reconciliation processes to support the monthly financial close and reporting requirements.
RFMS Core Business System Controls
The RFMS business system is an ERP software with integrated operations, inventory and accounting. The system processes transactions as it simultaneously records them in journals and ledgers and uses this data to produce financial statements. The system provides a “book of original entry” with the necessary subsidiary details that tie to the general ledger to facilitate a comprehensive audit trail.
The subsidiary ledgers are:
- Accounts Receivable
- Customer Deposits
- Accounts Payable
- Cash and Checking Accounts
- Inventory
Customer orders are generated using a system controlled sequential control number, with separate ranges for each company/store code. These numbers control the sales transaction throughout the system, including the generation of a PO, work order, AR and job costing. These system reference control numbers govern the transaction history from point of sale and cannot be changed or deleted.
Payments made against these orders are given sequential receipt numbers which in turn must balance against the cash deposits made to each bank account. These deposits must include a range of receipts with no blanks and must begin with the first receipt number that has not been posted. This ensures that all payments received for a customer’s account will be posted to the cash account.
Inventory is assigned on a line by line basis to individual orders. The costs associated with each line is recorded from the individual inventory record, which in turn has had cost recorded from the vendor’s invoice. The final cost is not assigned against the customer order until the vendor invoice is costed to Accounts Payable. The system is designed to not allow inventory withdrawal (debit to COGS, credit to inventory) prior to the cost verification (cost recorded from vendor’s invoice).
Service costs are assigned to the individual orders based on the actual costs from the invoices submitted by sub-contractors (installers). These costs are recorded by specific product and work type to enhance internal reporting and tracking. The actual invoices are posted to the journal as paid labor at the time the AP or Payroll check is issued. The system does not accrue labor invoices entered but not paid.
Once an order has been completed (delivered and installed), it is job costed which represents closing the order. At that point the sales order becomes a billed (invoiced) job. The control number generated at the point of written sales continues to be the reference point. The system will generate entries to record sales, AR, inventory release, cost of goods and apply deposits taken. The date on which the revenue is to be recognized is user controlled to permit recognition of sales in the correct accounting period. It is not necessary to postpone entries of any type into the RFMS system in the current period due to a prior period remaining open.
RFMS requires that sales and use tax information be set for each company on a global level, as well as the city and county level. This tax information is applied at the time the customer order is entered and a report is provided to review before the monthly sales tax total liability is manually entered for the month end journal. Tax altering can be restricted if configured within the System Options.
Inventory values are based on a perpetual inventory system that considers available, on order and reserved inventory statuses. Valuation reports can segregate inventory by company or store code, by product category, with quantity, costs and extensions. All records have a complete inventory history with the date received, original amount received, inventory assigned and used, and current amount available.
Enhanced Revenue Recognition Method Accounting (ERRM)
To assist with compliance with SOX regulations, RFMS developed the Enhanced Revenue Recognition Method or ERRM. ERRM is a feature in RFMS designed to allow complete detail in the journal. It utilizes new Standard Account Codes for enhanced journal reporting and real-time journal postings. This enables a user to run a preliminary journal close at any point during a month with the most up-to-date activity.
These added detail postings separate the journal summary reports for A/R, A/P, Customer Deposits, Sales, Cost of Sales and Inventory into a detailed listing that shows when specific transactions are made. ERRM also provides a more detailed journal listing than what is currently included in RFMS particularly relating to material and labor Work In Progress tracking through the journal.
The ERRM option is designed to allow more detail in the journal by doing the following:
- Most activities generated in RFMS post to the journal immediately.
- Posts specific transactions instead of traditional journal summary reports for A/R, A/P, Customer Deposits, Sales, Cost of Sales and Inventory
- Batch numbers are generated to track these transactions. The batch numbers are a set of journal entries for one specific procedure, meaning every transaction has its own batch number. They are assigned to each journal posting where you can filter and track information based on these batch numbers.
- Additional sub-ledgers can be reconciled including Work in Process Material and Service, Accrued Labor, Accrued Inventory, and Unbilled A/R.
RFMS Enterprise Manager Security
The best plan of action for SOX compliance is to have the correct security controls in place to ensure that financial data is accurate and protected against loss. For this reason, RFMS Enterprise Manager was developed. The RFMS Enterprise Manager feature provides for enhanced security system as well as an audit tracking function. The program uses the SQL Database and Windows Authentication to track data base activity and control system access at both the user and group level.
Each user’s Login ID is used to determine their specific rights and permissions to access various programs and features in RFMS. This represents an alternative to the standard password security already in place in the RFMS core system, in which certain programs or functions are password protected based on levels of security. Using Enterprise Manager eliminates the need to enter passwords repeatedly, it only allows the user to enter areas of the system they have been assigned.
Because the user enters the system using a unique login ID, rather than a generic password, RFMS can track which user made any changes in the data. For example, it can track adding, changing or deleting an order line. The audit features are customizable and are controlled by an RFMS Administrator inside of Enterprise Manager.
RFMS Enterprise Manager does meet compliance requirements because it can monitor data, enforce policies, and log every user action. With evidentiary-quality trails, all the data needed for compliance is in place. Protect your data and your business to ensures SOX compliance and rest a little easier during your next audit.
RFMS Sarbanes-Oxley Compliance
Below are the specific control methods that the RFMS software utilizes to achieve compliance with Sarbanes-Oxley with regards to data integrity, reporting and security.
☑Establish safeguards to prevent data tampering (Section 302.2)
Implement an ERP system that tracks user logins access to all computers that contain sensitive data and detects break-in attempts to computers, databases, fixed and removable storage, and websites.
RFMS running the Enterprise Manager security system utilizes Windows Authentication for user login to computer, networks, and RFMS programs. Best practices should be followed to keep information secure, like requiring complicated passwords and requiring frequent password changes.
When a user runs RFMS from their workstation or remote session, an SQL ODBC type call is made to the SQL Server to verify if this user is valid and has appropriate rights to the SQL Server via windows authentication. The user will be checked in Enterprise Manager to see if they are valid and has roles assigned for RFMS. If the user has been disabled in the Active Directory, they are disabled from here as well.
Since the Active Directory user is used to sign into the workstation or remote session, this account can be used to clear Remote Desktop Locks as well as SQL Locks. RFMS pulls the account made by that user within RFMS as well to note changes made by that user
☑Establish safeguards to establish timelines. (Section 302.3)
Implement an ERP system that timestamps all data as it is received in real-time. This data should be stored at a remote location as soon as it is received, thereby preventing data alteration or loss. In addition, log information should be moved to a secure location and an encrypted MD5 checksum created, thereby preventing any tampering.
As data is added into RFMS, the database is automatically tracking the date and time it was added as well as establishing the computer and logged on user that added the data. As you can see below in this screenshot of RFMS data, the CAPS represent the computer, after the “:” represents the user. This information is not editable by the user and cannot be manipulated.
☑Establish verifiable controls to track data access. (Section 302.4.B)
Implement an ERP system that can receive data messages from virtually an unlimited number of sources. Collection of data should be supported from file queues, FTP transfers, and databases, independent of the actual framework used, such as COBIT and ISO/IEC 27000.
Information that is transferred into RFMS automatically is done within the confines of our proprietary application interface (API). Our API is controlled by RFMS exclusively to ensure data transmitted using the API conforms to the same standards required when data is entered manually.
☑Ensure that safeguards are operational. (Section 302.4.C)
Implement an ERP system that can issue daily reports to e-mail addresses and distribute reports via RSS, making it easy to verify that the system is up and running from any location.
Select reports in RFMS can be configured to auto run and email select recipients. Emails can be set to run daily, weekly, or more frequently.
Once the report is configured, the parameters of the report are saved. The saved report can then be automated utilizing Windows Task Scheduler. Consult your IT professional on configuring this to work for your company.
☑Disclose security safeguards to SOX auditors. (Section 404.A.1.1)
Implement an ERP system that provides access to auditors using role-based permissions. Auditors may be permitted complete access to specific reports and facilities without the ability to actually make changes to these components or reconfigure the system.
Enterprise Manager Security system utilizes role-based permissions to control access to various modules and functions within RFMS. Auditors can be setup to only have access to run reports with no ability whatsoever to edit any data.
You can assign the all Auditors a group and then control access to what that group has the ability to see, or roles can be set individually per user.
Comments
Please sign in to leave a comment.